The Sakura Internet hack may have affected as many as 1,360,563 customer accounts after attackers accessed a sales management system that stored contract and membership information.
The Japanese cloud and data-centre provider said the figure remains preliminary. Its investigation is still underway, and the final number of affected accounts has not yet been confirmed.
Sakura Internet provides web hosting, virtual private servers, public cloud services, data-centre capacity and GPU computing. It also serves as a domestic provider for Japan’s Government Cloud programme.
Sakura Internet hack exposed sales management system
The company said attackers accessed its IT systems on August 9.
Investigators discovered the larger incident while examining a separate unauthorised-access case involving Sakura Rental Server, one of the company’s hosting services. Sakura Internet has not confirmed whether the two incidents are related.
The Rental Server incident involved unauthorised logins to 583 accounts. Attackers accessed customer-facing systems and client data, and Sakura found malware in its environment.
The company invalidated abused credentials and removed the malware. However, the discovery of access to the sales management system significantly expanded the potential scale of the security incident.
Up to 1.36 million accounts may be affected
The potentially affected system stored customer contract and membership information.
Sakura Internet said it has not confirmed whether attackers exfiltrated any data. The company also stated that the compromised system did not store credit-card information.
Stored passwords use hashing, which should make them difficult to decipher if stolen. However, customers should still remain cautious, especially if they receive unexpected messages referring to their account or contract details.
Sakura Internet has notified relevant authorities and is contacting affected customers individually as the investigation continues.
Company says attack was not ransomware-related
The company has not disclosed the type of malware found in its systems. It also has not reported operational or service disruptions linked to the incident.
A Sakura Internet spokesperson later said the attack was not related to ransomware and did not involve a ransom demand. The company declined to provide further information about the malware, citing security considerations.
The Sakura Internet hack highlights the risk that can follow a security incident even when no confirmed data theft has emerged. Customers should monitor official notifications, review account security settings and remain alert to phishing attempts that may exploit concern around the breach.


0 responses to “Sakura Internet Hack May Affect 1.36M Accounts”